Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Blackbeltstudio Most Popular Ringtones | 9/9/2014 | 17/6/2026 | The Most Popular Ringtones (aka com.bbs.mostpopularringtones) application 32 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.1) | 1.2% | — | Blackberry OSBlackberry Q10Blackberry Q5Blackberry Z10+1 | 18/8/2014 | 17/6/2026 | The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in… | |
| Modificada | Media (4.9) | 0.38% | — | Blackberry Enterprise ServiceBlackberry Enterprise ServerBlackberry Enterprise Server Express | 18/8/2014 | 17/6/2026 | BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file. | |
| Modificada | Media (6.8) | 0.61% | — | Carbonblack Carbon Black | 22/4/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative users and have other unspecified action, as demonstrated by a request to api/user. | |
| Modificada | Alta (9.3) | 5.7% | — | Blackberry OSBlackberry Z10 | 12/4/2014 | 17/6/2026 | Stack-based buffer overflow in a certain decryption function in qconnDoor on BlackBerry Z10 devices with software 10.1.0.2312, when developer-mode has been previously enabled, allows remote attackers to execute arbitrary code via a crafted packet in a TCP session on a wireless network. | |
| Modificada | Media (4.9) | 0.95% | 💥 Exploit | Blackberry QNX Neutrino Rtos | 18/3/2014 | 17/6/2026 | /sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow. | |
| Modificada | Alta (7.2) | 2.9% | 💥 Exploit | Blackberry QNX Neutrino Rtos | 18/3/2014 | 17/6/2026 | /sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument. | |
| Modificada | Media (4.3) | 1.8% | — | Blackboard Vista/ce | 22/2/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Blackboard Vista/CE 8.0 SP6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.3% | — | Blackberry Enterprise ServiceBlackberry Universal Device ServiceBlackberry Enterprise ServerBlackberry Enterprise Server Express | 14/2/2014 | 17/6/2026 | BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Express for Exchange through 5.0.4, Enterprise Server for Domino through 5.0.4 MR6, Enterprise Server for Exchange through 5.0.4 MR6, and Enterprise Server for GroupWise… | |
| Modificada | Media (6.8) | 1.4% | 💥 Exploit | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 220 | 21/1/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts via a crafted request to admin/access_control_user_add.php; (2) modify or (3)… | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Seagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 220 | 9/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname parameter to admin/access_control_user_edit.php or (2) workname parameter to admin/network_workgroup_domain.php. | |
| Modificada | Media (6.8) | 0.91% | — | Blackberry Link | 18/11/2013 | 16/6/2026 | BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding. | |
| Modificada | Media (5.8) | 1.9% | — | Blackberry Link | 18/11/2013 | 17/6/2026 | BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer Manager in certain situations involving successive logins with different accounts, which allows context-dependent attackers to bypass intended restrictions on remote… | |
| Modificada | Alta (7.9) | 0.96% | — | Blackberry Enterprise Service | 11/10/2013 | 16/6/2026 | The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to upload and execute arbitrary packages via a request to port 1098. | |
| Modificada | Media (6.2) | 0.35% | — | Blackberry OSBlackberry Z10 | 13/7/2013 | 16/6/2026 | BlackBerry 10 OS before 10.0.10.648 on BlackBerry Z10 smartphones uses weak permissions for a BlackBerry Protect object, which allows physically proximate attackers to bypass intended access restrictions by leveraging a user's BlackBerry Protect password-reset request and a user's installation of a crafted application. | |
| Modificada | Media (5.4) | 6.7% | — | Blackberry QNX Software Development PlatformBlackberry QNX Neutrino Rtos | 12/7/2013 | 16/6/2026 | Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868 that leverage improper handling of the /dev/photon… | |
| Modificada | Alta (7.8) | 8.2% | — | Blackberry QNX Momentics Tool SuiteBlackberry QNX Software Development PlatformBlackberry QNX Neutrino Rtos | 12/7/2013 | 16/6/2026 | Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool Suite through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via… | |
| Modificada | Alta (10) | 4.4% | — | Seagate Blackarmor NAS | 25/5/2012 | 16/6/2026 | d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors. | |
| Modificada | Alta (7.9) | 6.5% | — | SambaRIM Blackberry Playbook TabletRIM Blackberry Playbook OS | 23/2/2012 | 16/6/2026 | Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers… | |
| Modificada | Media (5.8) | 0.96% | — | Ming Blacklist Free | 25/1/2012 | 16/6/2026 | The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists and a contact list via a crafted application that launches a "data-flow attack." | |
| Modificada | Alta (7.2) | 0.36% | — | Blackberry Tablet OS | 8/12/2011 | 16/6/2026 | The BlackBerry PlayBook service on the Research In Motion (RIM) BlackBerry PlayBook tablet with software before 1.0.8.6067 allows local users to gain privileges via a crafted configuration file in a backup archive. | |
| Modificada | Media (6.5) | 2.1% | — | RIM Blackberry Enterprise Server | 21/10/2011 | 16/6/2026 | The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact… | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Ulyssesonline Black-letterhead | 28/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | |
| Modificada | Media (6.4) | 2.2% | — | RIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server Express | 14/7/2011 | 16/6/2026 | Unspecified vulnerability in the BlackBerry Administration API in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 5.0.1 through 5.0.3, and BlackBerry Enterprise Server Express software 5.0.1 through 5.0.3, allows remote attackers to read text files or cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 1.9% | — | RIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server Express | 18/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webdesktop/app in the BlackBerry Web Desktop Manager component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software before 5.0.2 MR5 and 5.0.3 before MR1, and BlackBerry Enterprise Server Express software 5.0.1 and 5.0.2, allows remote attackers to inject… |